in

Microsoft April 2020 Patch Tuesday comes with fixes for three zero-days

Microsoft logoImage: ZDNet

Microsoft has published today its monthly roll-up of security updates known as Patch Tuesday.

This month’s updates are a bulky release. The OS maker has made available patches today for 113 vulnerabilities across 11 products, including three zero-day bugs that were being actively exploited in the wild.

As always, details remain scant for the time being. Details about zero-day attacks are usually kept under wraps for days or weeks, to give users time to patch and prevent attackers from developing proof-of-concept code.

The three zero-days patched this month are:

CVE-2020-1020 – A vulnerability in the Windows Adobe Type Manager Library lets attacker run code on vulnerable systems. Attacks can be executed remotely. The zero-day does not impact Windows 10. Details about this zero-day became public last month, but a patch was only released today. Read more in our previous coverage here.
CVE-2020-0938 – This is a second bug in the same Windows Adobe Type Manager Library. Bug somewhat similar to the one above, but its existence was disclosed only today, unlike the first one. The Microsoft mitigations published last month, if applied, also blocked attacks exploiting this second bug.
CVE-2020-1027 – A bug in the Windows kernel lets attackers elevate privileges to run code with kernel access.
CVE-2020-0968 – ̶A̶ ̶b̶u̶g̶ ̶i̶n̶ ̶t̶h̶e̶ ̶I̶n̶t̶e̶r̶n̶e̶t̶ ̶E̶x̶p̶l̶o̶r̶e̶r̶ ̶s̶c̶r̶i̶p̶t̶i̶n̶g̶ ̶e̶n̶g̶i̶n̶e̶ ̶c̶a̶n̶ ̶a̶l̶l̶o̶w̶ ̶a̶t̶t̶a̶c̶k̶e̶r̶s̶ ̶t̶o̶ ̶t̶a̶k̶e̶ ̶c̶o̶n̶t̶r̶o̶l̶ ̶o̶f̶ ̶a̶ ̶r̶e̶m̶o̶t̶e̶ ̶s̶y̶s̶t̶e̶m̶.̶   After this article went live, Microsoft issued a correction on the CVE-2020-0968 security advisory to update its exploitation status. This bug has not been exploited in the wild before, hence, it is not a zero-day. Article content and title updated accordingly.

According to Microsoft, the first three zero-days were discovered and reported by Google’s two security teams — Project Zero and the Threat Analysis Group (TAG).

Lacking any other details, it is currently unclear if the three zero-days have been used by the same threat actor, or in the same hacking campaign.

Since Patch Tuesday updates are delivered in bulk, installing today’s updates fixes all three zero-days at once, along with the 109 other security bugs.

Additional information about this month’s Patch Tuesday is included below, including links to security fixes published by other companies:

Microsoft’s official Security Update Guide portal lists all security updates in a filterable table.
ZDNet has also put together this page listing all security updates on one single place.
Adobe’s security updates are detailed here.
SAP security updates are available here.
VMWare security updates are available here.
Google Chrome security updates were released last week, on April 7.
Oracle’s second CPU this year is available here.
The Android Security Bulletin for April 2020 is detailed here. Patches started rolling out to users’ phones last week.

TagCVE IDCVE Title
Android AppCVE-2020-0943Microsoft YourPhone Application for Android Authentication Bypass Vulnerability
AppsCVE-2020-1019Microsoft RMS Sharing App for Mac Elevation of Privilege Vulnerability
Microsoft DynamicsCVE-2020-1050Microsoft Dynamics 365 (On-Premise) Cross Site Scripting Vulnerability
Microsoft DynamicsCVE-2020-1018Microsoft Dynamics Business Central/NAV Information Disclosure
Microsoft DynamicsCVE-2020-1049Microsoft Dynamics 365 (On-Premise) Cross Site Scripting Vulnerability
Microsoft DynamicsCVE-2020-1022Dynamics Business Central Remote Code Execution Vulnerability
Microsoft Graphics ComponentCVE-2020-0952Windows GDI Information Disclosure Vulnerability
Microsoft Graphics ComponentCVE-2020-0938Adobe Font Manager Library Remote Code Execution Vulnerability
Microsoft Graphics ComponentCVE-2020-0687Microsoft Graphics Remote Code Execution Vulnerability
Microsoft Graphics ComponentCVE-2020-0987Microsoft Graphics Component Information Disclosure Vulnerability
Microsoft Graphics ComponentCVE-2020-1004Windows Graphics Component Elevation of Privilege Vulnerability
Microsoft Graphics ComponentCVE-2020-1005Microsoft Graphics Component Information Disclosure Vulnerability
Microsoft Graphics ComponentCVE-2020-0958Win32k Elevation of Privilege Vulnerability
Microsoft Graphics ComponentCVE-2020-0907Microsoft Graphics Components Remote Code Execution Vulnerability
Microsoft Graphics ComponentCVE-2020-0982Microsoft Graphics Component Information Disclosure Vulnerability
Microsoft Graphics ComponentCVE-2020-0964GDI+ Remote Code Execution Vulnerability
Microsoft Graphics ComponentCVE-2020-1020Adobe Font Manager Library Remote Code Execution Vulnerability
Microsoft Graphics ComponentCVE-2020-0784DirectX Elevation of Privilege Vulnerability
Microsoft JET Database EngineCVE-2020-0995Jet Database Engine Remote Code Execution Vulnerability
Microsoft JET Database EngineCVE-2020-0999Jet Database Engine Remote Code Execution Vulnerability
Microsoft JET Database EngineCVE-2020-0988Jet Database Engine Remote Code Execution Vulnerability
Microsoft JET Database EngineCVE-2020-0992Jet Database Engine Remote Code Execution Vulnerability
Microsoft JET Database EngineCVE-2020-0994Jet Database Engine Remote Code Execution Vulnerability
Microsoft JET Database EngineCVE-2020-0953Jet Database Engine Remote Code Execution Vulnerability
Microsoft JET Database EngineCVE-2020-0889Jet Database Engine Remote Code Execution Vulnerability
Microsoft JET Database EngineCVE-2020-0959Jet Database Engine Remote Code Execution Vulnerability
Microsoft JET Database EngineCVE-2020-0960Jet Database Engine Remote Code Execution Vulnerability
Microsoft JET Database EngineCVE-2020-1008Jet Database Engine Remote Code Execution Vulnerability
Microsoft OfficeCVE-2020-0979Microsoft Excel Remote Code Execution Vulnerability
Microsoft OfficeCVE-2020-0980Microsoft Word Remote Code Execution Vulnerability
Microsoft OfficeCVE-2020-0984Microsoft (MAU) Office Elevation of Privilege Vulnerability
Microsoft OfficeCVE-2020-0760Microsoft Office Remote Code Execution Vulnerability
Microsoft OfficeCVE-2020-0991Microsoft Office Remote Code Execution Vulnerability
Microsoft OfficeCVE-2020-0961Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability
Microsoft OfficeCVE-2020-0931Microsoft SharePoint Remote Code Execution Vulnerability
Microsoft OfficeCVE-2020-0906Microsoft Excel Remote Code Execution Vulnerability
Microsoft OfficeCVE-2020-0935OneDrive for Windows Elevation of Privilege Vulnerability
Microsoft Office SharePointCVE-2020-0927Microsoft Office SharePoint XSS Vulnerability
Microsoft Office SharePointCVE-2020-0923Microsoft Office SharePoint XSS Vulnerability
Microsoft Office SharePointCVE-2020-0925Microsoft Office SharePoint XSS Vulnerability
Microsoft Office SharePointCVE-2020-0924Microsoft Office SharePoint XSS Vulnerability
Microsoft Office SharePointCVE-2020-0932Microsoft SharePoint Remote Code Execution Vulnerability
Microsoft Office SharePointCVE-2020-0930Microsoft Office SharePoint XSS Vulnerability
Microsoft Office SharePointCVE-2020-0933Microsoft Office SharePoint XSS Vulnerability
Microsoft Office SharePointCVE-2020-0920Microsoft SharePoint Remote Code Execution Vulnerability
Microsoft Office SharePointCVE-2020-0929Microsoft SharePoint Remote Code Execution Vulnerability
Microsoft Office SharePointCVE-2020-0971Microsoft SharePoint Remote Code Execution Vulnerability
Microsoft Office SharePointCVE-2020-0975Microsoft SharePoint Spoofing Vulnerability
Microsoft Office SharePointCVE-2020-0978Microsoft Office SharePoint XSS Vulnerability
Microsoft Office SharePointCVE-2020-0977Microsoft SharePoint Spoofing Vulnerability
Microsoft Office SharePointCVE-2020-0976Microsoft SharePoint Spoofing Vulnerability
Microsoft Office SharePointCVE-2020-0974Microsoft SharePoint Remote Code Execution Vulnerability
Microsoft Office SharePointCVE-2020-0973Microsoft Office SharePoint XSS Vulnerability
Microsoft Office SharePointCVE-2020-0972Microsoft SharePoint Spoofing Vulnerability
Microsoft Office SharePointCVE-2020-0954Microsoft Office SharePoint XSS Vulnerability
Microsoft Office SharePointCVE-2020-0926Microsoft Office SharePoint XSS Vulnerability
Microsoft Scripting EngineCVE-2020-0968Scripting Engine Memory Corruption Vulnerability
Microsoft Scripting EngineCVE-2020-0966VBScript Remote Code Execution Vulnerability
Microsoft Scripting EngineCVE-2020-0895Windows VBScript Engine Remote Code Execution Vulnerability
Microsoft Scripting EngineCVE-2020-0969Chakra Scripting Engine Memory Corruption Vulnerability
Microsoft Scripting EngineCVE-2020-0970Scripting Engine Memory Corruption Vulnerability
Microsoft Scripting EngineCVE-2020-0967VBScript Remote Code Execution Vulnerability
Microsoft WindowsCVE-2020-0942Connected User Experiences and Telemetry Service Elevation of Privilege Vulnerability
Microsoft WindowsCVE-2020-0965Microsoft Windows Codecs Library Remote Code Execution Vulnerability
Microsoft WindowsCVE-2020-0940Windows Push Notification Service Elevation of Privilege Vulnerability
Microsoft WindowsCVE-2020-0934Windows Elevation of Privilege Vulnerability
Microsoft WindowsCVE-2020-1029Connected User Experiences and Telemetry Service Elevation of Privilege Vulnerability
Microsoft WindowsCVE-2020-1011Windows Elevation of Privilege Vulnerability
Microsoft WindowsCVE-2020-1094Windows Work Folder Service Elevation of Privilege Vulnerability
Microsoft WindowsCVE-2020-1016Windows Push Notification Service Information Disclosure Vulnerability
Microsoft WindowsCVE-2020-0794Windows Denial of Service Vulnerability
Microsoft WindowsCVE-2020-1017Windows Push Notification Service Elevation of Privilege Vulnerability
Microsoft WindowsCVE-2020-0944Connected User Experiences and Telemetry Service Elevation of Privilege Vulnerability
Microsoft WindowsCVE-2020-1006Windows Push Notification Service Elevation of Privilege Vulnerability
Microsoft WindowsCVE-2020-1009Windows Elevation of Privilege Vulnerability
Microsoft WindowsCVE-2020-0981Windows Token Security Feature Bypass Vulnerability
Microsoft WindowsCVE-2020-1001Windows Push Notification Service Elevation of Privilege Vulnerability
Microsoft Windows DNSCVE-2020-0993Windows DNS Denial of Service Vulnerability
Open Source SoftwareCVE-2020-1026MSR JavaScript Cryptography Library Security Feature Bypass Vulnerability
Remote Desktop ClientCVE-2020-0919Microsoft Remote Desktop App for Mac Elevation of Privilege Vulnerability
Visual StudioCVE-2020-0899Microsoft Visual Studio Elevation of Privilege Vulnerability
Visual StudioCVE-2020-0900Visual Studio Extension Installer Service Elevation of Privilege Vulnerability
Windows DefenderCVE-2020-1002Microsoft Defender Elevation of Privilege Vulnerability
Windows DefenderCVE-2020-0835Windows Defender Antimalware Platform Hard Link Elevation of Privilege Vulnerability
Windows Hyper-VCVE-2020-0918Windows Hyper-V Elevation of Privilege Vulnerability
Windows Hyper-VCVE-2020-0910Windows Hyper-V Remote Code Execution Vulnerability
Windows Hyper-VCVE-2020-0917Windows Hyper-V Elevation of Privilege Vulnerability
Windows KernelCVE-2020-0699Win32k Information Disclosure Vulnerability
Windows KernelCVE-2020-1027Windows Kernel Elevation of Privilege Vulnerability
Windows KernelCVE-2020-1003Windows Kernel Elevation of Privilege Vulnerability
Windows KernelCVE-2020-0955Windows Kernel Information Disclosure in CPU Memory Access
Windows KernelCVE-2020-1015Windows Elevation of Privilege Vulnerability
Windows KernelCVE-2020-1000Windows Kernel Elevation of Privilege Vulnerability
Windows KernelCVE-2020-1007Windows Kernel Information Disclosure Vulnerability
Windows KernelCVE-2020-0957Win32k Elevation of Privilege Vulnerability
Windows KernelCVE-2020-0936Windows Scheduled Task Elevation of Privilege Vulnerability
Windows KernelCVE-2020-0956Win32k Elevation of Privilege Vulnerability
Windows KernelCVE-2020-0962Win32k Information Disclosure Vulnerability
Windows KernelCVE-2020-0821Windows Kernel Information Disclosure Vulnerability
Windows KernelCVE-2020-0913Windows Kernel Elevation of Privilege Vulnerability
Windows KernelCVE-2020-0888DirectX Elevation of Privilege Vulnerability
Windows MediaCVE-2020-0948Media Foundation Memory Corruption Vulnerability
Windows MediaCVE-2020-0937Media Foundation Information Disclosure Vulnerability
Windows MediaCVE-2020-0949Media Foundation Memory Corruption Vulnerability
Windows MediaCVE-2020-0939Media Foundation Information Disclosure Vulnerability
Windows MediaCVE-2020-0950Media Foundation Memory Corruption Vulnerability
Windows MediaCVE-2020-0946Media Foundation Information Disclosure Vulnerability
Windows MediaCVE-2020-0947Media Foundation Information Disclosure Vulnerability
Windows MediaCVE-2020-0945Media Foundation Information Disclosure Vulnerability
Windows Update StackCVE-2020-0996Windows Update Stack Elevation of Privilege Vulnerability
Windows Update StackCVE-2020-1014Microsoft Windows Update Client Elevation of Privilege Vulnerability
Windows Update StackCVE-2020-0983Windows Elevation of Privilege Vulnerability
Windows Update StackCVE-2020-0985Windows Update Stack Elevation of Privilege Vulnerability


Source: Information Technologies - zdnet.com

Microsoft pushes back end of support date for Windows 10 1809

How Verizon Media's networking team is handling COVID-19 supply chain challenges